Today
Top Secret
Unspecified
CI Polygraph
IT - Security
va, VA (On-Site/Office)
Marathon TS is looking for an Information Systems Security Manager to support our efforts at DISA.
Key Responsibilities:
Minimum Requirements:
Desired Skills & Qualifications:
#CJJOBS
Key Responsibilities:
- Information Security Program Development:
- Develop, implement, and maintain a comprehensive information security program that includes policies, procedures, and guidelines to protect the organization's information assets.
- Regularly review and update the information security program to ensure it remains effective and aligned with industry best practices and regulatory requirements.
- Regulatory Compliance:
- Ensure that the organization's information systems comply with all applicable security regulations and standards, including NIST, FISMA, and the Joint Special Access Program Implementation Guide (JSIG).
- Conduct regular audits and assessments to verify compliance and address any identified gaps.
- Security Controls Implementation:
- Lead the implementation and maintenance of security controls, such as access controls, data encryption, and vulnerability management.
- Collaborate with IT and other departments to integrate security controls into existing and new systems.
- Incident Response Management:
- Manage the organization's security incident response process, including the investigation of security incidents and coordination with internal and external stakeholders to resolve incidents.
- Develop and maintain an incident response plan, conduct regular drills, and ensure all relevant personnel are trained on incident response procedures.
- Technical Guidance and Support:
- Provide guidance and support to technical teams in the development and implementation of security solutions and technologies.
- Stay current with emerging security trends, threats, and technologies to provide informed recommendations.
- Risk Assessment and Mitigation:
- Conduct security risk assessments to identify potential threats and vulnerabilities.
- Develop and implement risk mitigation strategies to address identified risks, including the creation of risk management plans and the prioritization of security initiatives.
- Documentation and Compliance:
- Generate and maintain documentation required for Risk Management Framework (RMF) processes, including Standard Operating Procedures (SOPs), security plans, risk assessments, and Plans of Action and Milestones (POA&M).
- Ensure compliance with the Joint Special Access Program Implementation Guide (JSIG) and other relevant security standards and policies.
- External Stakeholder Engagement:
- Represent the organization in meetings and communications with external stakeholders, including government agencies, auditors, and vendors.
- Prepare and present security reports and updates to senior management and external parties as required.
- Continuous Improvement:
- Continuously monitor and evaluate the effectiveness of the information security program and make improvements as necessary.
- Foster a culture of continuous improvement by encouraging feedback and collaboration across the organization.
Minimum Requirements:
- Candidates must have an active TS/SCI clearance with the ability to obtain CI Poly.
- IAM level III certification (GSLC, CISM, CISSP, CCISO), or ability to obtain certification within six months of hiring.
- A Bachelor's degree in a relevant field (e.g., Computer Science, Information Systems Management, Engineering) is required for this position.
- 4 years of relevant work experience may be considered in lieu of the degree requirement.
- 8 years of experience in cybersecurity or a related field, with prior experience in a leadership role
- 2+ years of cybersecurity experience in the Department of Defense (DoD) or Intelligence community.
- Strong knowledge of cybersecurity principles, tools, and techniques.
- Security+ or equivalent (DoD 8570) if currently no IAM Level III certifications above
- Strong leadership experience and proactive drive.
Desired Skills & Qualifications:
- Experience as a Cyber or Security Analyst or Security Control Assessor (SCA) for federal information systems.
- Experience with the Special Access Programs (SAPs) and Intelligence Community (IC).
- Knowledge and/or understanding of Joint Special Access Program Implementation Guide (JSIG)
- The ability to adapt in fast paced environments, comfort with ambiguity.
- Familiarity with cloud technologies, security practices, and agile methodologies.
- Strong self-organization and self-management skills with emphasis on self-initiation and follow through.
- Proven written and oral communication skills.
- Demonstrated ability to build trusted advisor relationships with clients.
#CJJOBS
group id: 10362312